OIC OIC Technology & Digital Investigations 2 — Questions and Answers
Question 1: Which legal authority is typically required before an OIC inspector can access private electronic records stored on a third-party server?
- A valid subpoena or court order directed to the service provider (Correct answer)
- An internal agency authorization memo
- The subject's verbal consent recorded on video
- A departmental inspection warrant covering physical premises
Correct answer: A valid subpoena or court order directed to the service provider
Accessing private electronic records held by third-party providers requires a subpoena or court order under the Electronic Communications Privacy Act.
Question 2: Social media data collected during an OIC investigation should be preserved using:
- Screenshots with timestamps and URL documentation, or a certified capture tool (Correct answer)
- Printouts from a standard web browser with no additional documentation
- The investigator's personal social media account to save copies
- Verbal notes describing the content observed
Correct answer: Screenshots with timestamps and URL documentation, or a certified capture tool
Social media evidence must be captured with verifiable timestamps and source URLs, ideally using certified tools, to establish authenticity.
Question 3: When an investigation involves encrypted files that cannot be accessed, an OIC inspector should:
- Document the encrypted files and consult a digital forensics specialist or legal counsel for decryption options (Correct answer)
- Delete the files and note they were inaccessible in the report
- Request the subject provide the password under threat of arrest
- Assume the files are irrelevant since they cannot be opened
Correct answer: Document the encrypted files and consult a digital forensics specialist or legal counsel for decryption options
Encrypted files must be documented, and legal options including compelling decryption or using forensic tools should be explored with specialists.
Question 4: IP address logs obtained during a digital investigation are best used to:
- Identify the origin of network activity and associate it with a location or account (Correct answer)
- Prove beyond doubt the identity of the individual who committed a crime
- Replace the need for physical surveillance in cybercrime cases
- Establish the financial value of data transferred over a network
Correct answer: Identify the origin of network activity and associate it with a location or account
IP logs identify network activity origins and can be corroborated with other evidence, but alone they do not conclusively identify an individual.
Question 5: In the context of OIC digital investigations, 'chain of custody' for electronic evidence means:
- A documented record of every person who accessed or handled the evidence from seizure to court (Correct answer)
- The sequence of technical steps used during forensic imaging
- The order in which digital files were collected from a device
- The encryption hierarchy protecting evidence files on a server
Correct answer: A documented record of every person who accessed or handled the evidence from seizure to court
Chain of custody is the documented history of who handled evidence, ensuring it has not been tampered with between collection and presentation.
Question 6: An OIC inspector discovers deleted files on a seized computer. These files:
- May be recoverable using forensic software and are potentially admissible as evidence (Correct answer)
- Are permanently destroyed and cannot be used in any proceeding
- Can only be recovered by the original manufacturer
- Must be ignored since deletion constitutes legal disposal
Correct answer: May be recoverable using forensic software and are potentially admissible as evidence
Deleted files often remain recoverable from unallocated disk space using forensic tools until they are overwritten.
Which legal authority is typically required before an OIC inspector can access private electronic records stored on a third-party server?